North Korean state-backed hacking group Kimsuky is increasingly incorporating artificial intelligence into its cyber operations, using locally hosted AI systems to support malware development, data analysis, phishing campaigns and attack automation targeting cryptocurrency and financial organizations.
South Korean cybersecurity firm Genians says it has identified evidence that Kimsuky is moving beyond occasional experimentation with generative AI and is actively preparing to integrate AI into its broader attack infrastructure.
The findings suggest that AI is becoming an operational tool for the group rather than simply an experimental technology.
Kimsuky Builds Its Own Local AI Infrastructure
According to Genians, Kimsuky-affiliated operators have established at least three locally hosted large language model environments using platforms including Ollama, GPT4All and Msty.
Running AI models locally gives attackers an important advantage: they can interact with AI systems without necessarily sending sensitive information to external cloud providers.
The environments also support retrieval-augmented generation, allowing attackers to combine AI models with their own collections of documents and information.
Genians identified additional libraries and frameworks that could allow AI models to be incorporated into custom software.
The group has also reportedly collected tools including the Cursor AI coding assistant and speech-to-text technologies.
The apparent objective is to use existing AI capabilities across several stages of cyber operations, including malware development, information processing and automation.
Importantly, researchers do not currently believe Kimsuky is developing completely new foundation models.
Instead, the group appears to be adapting existing open-source AI technologies for offensive cybersecurity operations.
AI Makes Crypto Phishing More Convincing
Kimsuky’s use of AI extends beyond backend infrastructure.
Genians also identified evidence that the group continues to generate sophisticated phishing materials focused on cryptocurrency, investment strategies and financial technology services.
Some of the documents reportedly imitate legitimate Korean investment platforms and use polished language, consistent formatting and professional design elements.
AI-generated content can make these campaigns significantly harder for victims to identify.
Instead of relying on obvious grammatical mistakes or poorly designed documents, attackers can produce convincing materials tailored to specific industries, companies or individuals.
For cryptocurrency companies, this creates an especially serious threat because employees frequently interact with wallets, exchanges, private keys, treasury systems and other highly sensitive infrastructure.
North Korea Continues to Target Crypto
Kimsuky’s AI adoption comes against the backdrop of North Korea’s broader cryptocurrency theft campaign.
According to Chainalysis, North Korean-linked hackers stole approximately $2.02 billion in cryptocurrency during 2025, including the $1.5 billion Bybit attack, one of the largest crypto thefts ever recorded.
The group’s methods extend well beyond traditional phishing.
North Korean operators have reportedly used social engineering, malicious documents, fake employment schemes and infiltration of technology companies to obtain access to sensitive systems.
AI gives attackers another layer of capability by helping them scale and personalize these operations.
AI Is Changing the Cybersecurity Arms Race
The Kimsuky findings highlight a broader shift in cybersecurity.
AI is becoming useful to both defenders and attackers.
Hackers can potentially use AI to analyze code, generate malicious content, automate repetitive tasks, translate communications, conduct research and create more convincing social-engineering campaigns.
Defenders, meanwhile, are also deploying AI to detect suspicious behavior and identify vulnerabilities.
That creates an increasingly competitive cycle.
NEAR Protocol co-founder Illia Polosukhin has previously warned that AI could accelerate hackers’ ability to discover software vulnerabilities faster than traditional security teams can identify and patch them.
The result could be a growing gap between the speed of automated attacks and the speed of conventional cybersecurity processes.
The Coldcard Incident Raises Further Questions
Recent cryptocurrency security incidents have also intensified concerns about AI-assisted vulnerability discovery.
The approximately $100 million Coldcard-related Bitcoin wallet exploit has been discussed in connection with the possibility that an obscure vulnerability was identified using AI-assisted analysis.
While the precise role of AI in that incident remains subject to investigation, the case illustrates the broader concern: attackers may increasingly use machine intelligence to search for weaknesses that human security teams overlook.
For crypto companies, the implications are significant.
Blockchain networks may be highly transparent and cryptographically secured, but the applications, wallets, employees and infrastructure surrounding them can still become attack vectors.
The Bigger Threat Is AI-Powered Scale
Kimsuky’s activity demonstrates that the most important development may not be the creation of entirely new AI hacking techniques.
It may simply be the industrialization of existing attacks.
AI can help attackers produce more convincing phishing materials, analyze larger amounts of information, automate development tasks and adapt campaigns to specific targets.
For cryptocurrency firms holding large amounts of digital assets, that creates a particularly dangerous combination.
The blockchain may remain difficult to compromise, but the people and systems controlling billions of dollars in crypto remain attractive targets.
As state-backed groups increasingly integrate AI into their operations, crypto companies may need to treat AI-assisted attacks as a standard part of their security threat model rather than an emerging possibility.

